Companies can be held criminally liable too. A good compliance programme prevents it.

Prevention model · Whistleblowing channel · Corporate criminal defence

What does our service include?

From the risk analysis to defence in court if it ever comes to that. We design, implement and maintain criminal compliance programmes tailored to the reality of each company.

  • Corporate criminal risk analysis
  • Design of the prevention model (art. 31 bis of the Spanish Criminal Code)
  • Internal whistleblowing channel
  • Incident response protocol
  • Training for employees and management
  • Regular updates and review of the model
  • Criminal defence of legal entities
  • Internal investigations
  • Coordination with management and the board of directors
  • Compliance due diligence in M&A transactions
  • Employment compliance
  • GDPR and technology compliance

Art. 31 bis of the Spanish Criminal Code: what you need to know

Since the 2015 reform of the Spanish Criminal Code, legal entities — companies, associations, foundations — can be held criminally liable for offences committed by their directors, managers or employees in the name and for the benefit of the company.

The penalties for legal entities are severe: fines of up to twice the profit obtained, dissolution of the company, suspension of activities for up to 5 years, and bans on contracting with the public sector or receiving grants.

However, the same Article 31 bis provides that the company is exempt from liability — or the penalty is significantly reduced — if it has adopted and effectively implemented an organisation and management model that prevents these offences.

Criminal compliance is not just an obligation for large corporations. Any company — including SMEs and self-employed professionals operating through a company — is subject to the corporate criminal liability regime.

The advantages of having a compliance model

Exemption from or reduction of the penalty

If the company has an effective prevention model and the offence is committed by circumventing its controls, the company may be exempt from criminal liability.

A stronger corporate culture

A well-implemented compliance programme builds an internal culture of integrity that reduces workplace disputes and protects the company's reputation.

Access to public tenders and grants

Many public contracts and grant programmes require proof that the company has no criminal convictions. Compliance reduces that risk.

Trust from clients and investors

Companies with solid compliance programmes inspire greater confidence in due diligence processes, investment rounds and commercial relationships with large clients.

The offences that most often give rise to corporate criminal liability

The Spanish Criminal Code sets out a closed list of offences that can trigger criminal liability for legal entities. These are the most common in mid-sized companies and SMEs:

Tax fraud

Defrauding the Spanish tax authority (Hacienda) or Social Security. It is one of the most common economic offences and carries the highest reputational risk.

Money laundering

Especially relevant in the real estate, financial, advisory and international trade sectors. Anti-money-laundering regulations impose specific obligations.

Private-sector bribery

Payments or benefits given to executives of other companies to win contracts or favourable decisions. A real risk in companies with active sales teams.

Privacy offences

GDPR breaches that lead to the unlawful use of personal data, unauthorised access or disclosure of confidential information about clients or employees.

Employment offences

Imposing working conditions that infringe employees' rights, or workplace or sexual harassment within the company without preventive measures in place.

Environmental offences

Pollution of soil, water or the atmosphere through discharges or emissions. Manufacturing, construction and logistics businesses have high exposure.

The compliance model implementation process

There is no one-size-fits-all model. Compliance must be tailored to the activity, size, structure and specific risks of each organisation. This is how we work.

1

Initial assessment

We analyse the company's activity, its organisational structure, key processes and the criminal risks specific to its sector. Interviews with management and key departments.

2

Risk map

We identify and assess the specific criminal risks the company is exposed to: likelihood, impact and existing controls. This is the foundation of the model.

3

Model design

We draft the Organisation, Management and Control Model: policies, procedures, code of ethics, whistleblowing channel, compliance body and response protocols.

4

Training and roll-out

Training sessions for employees and management, adapted to each level. The model is only effective if the people in the organisation know it and apply it.

5

Monitoring and review

Compliance is not a document to be filed away. We carry out regular reviews to adapt the model to regulatory, organisational or business changes.

Does your company have a criminal compliance programme?

If the answer is no — or if you are not sure whether the one you have is robust enough — it is time to talk to us. The first consultation is free and comes with no obligation.

Request a free consultation Direct WhatsApp
Let's talk